Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://discord.com/press-releases/discord-launches-teen-by-...

> For the majority of adult users, we will be able to confirm your age group using information we already have. We use age prediction to determine, with high confidence, when a user is an adult. This allows many adults to access age-appropriate features without completing an explicit age check.

> Facial scans never leave your device. Discord and our vendor partners never receive it. IDs are used to get your age only and then deleted. Discord only receives your age — that’s it. Your identity is never associated with your account.

> We leverage an advanced machine learning model developed at Discord to predict whether a user falls into a particular age group based on patterns of user behavior and several other signals associated with their account on Discord. We only use these signals to assign users to an age group when our confidence level is high; when it isn't, users go through our standard age assurance flow to confirm their age. We do not use your message content in the age estimation model.

I work with corporate privacy all of the time, and there is actually something really interesting going on here. We're basically never allowed to claim legal compliance using heuristics or predictive models. Like, never ever. They demand a paper trail on everything, and telling our legal team that we are going to leave it to an algorithm on a user device would make them foam at the mouth.

They are basically trusting a piece of software to look at your face or ID in the same way that, like, a server at a restaurant would check before serving you alcohol.

I am curious to see if this kind of software compliance in the long run is even allowable by regulators.



For the United Kingdom specifically, I've suffered the misfortune of reading the Online Safety Act, and this kind of age estimation is both mentioned and permitted by the Act. (Not a lawyer blah blah blah)

Part 3, Chapter 2, Section 12(4) specifies that user-to-user service providers are required to use either age verification or age estimation (or both!) to prevent children from accessing content that is harmful to children. Section 12(6) goes on to state that "the age verification or age estimation must be of such a kind, and used in such a way, that it is highly effective at correctly determining whether or not a particular user is a child."

Part 12, Section 230(4) rules out self-declaration of age as being a form of age verification/estimation.

So I suppose it'll come down to whether or not Ofcom deems Discord's age estimation as "highly effective".

[Part 3, Chapter 2, Section 12(4)]: https://www.legislation.gov.uk/ukpga/2023/50/part/3/chapter/...

This is unrelated, but something I find interesting is that Category 1 user-to-user services (of which Discord is one, as per The Online Safety Act 2023 (Category 1, Category 2A and Category 2B Threshold Conditions) Regulations 2025) are required by Part 4, Chapter 1, Section 64(1) to "offer all adult users of the service the option to verify their identity (if identity verification is not required for access to the service).".


Part of me is wondering if we are all collectively misreading Discord's intent.

They have devised a system so lackluster and unverifyable that they can claim they are following the letter without having to turn over anything remotely useful to actually verify or track people's identities.


I get the impression that is part of Discord's intent they are signalling here and a lot of the response has been maybe a bit overly vitriolic in the face of that seeming message of "we are complying with the laws because we have to, but we are doing a bare minimum to do that". Especially relating those parts of the press release to the call for a Council of Teens and increased feedback.

It feels like a modern iteration of the game of way most bars check IDs: it's a bit of an honor system most nights and for most people. On days or events of increased scrutiny they put a bouncer out front. They make a show of doing it, but at the end of the day they want to sell product and not do paperwork, so it will be the bare minimum to keep the (international) law of of Discord's back. Discord seems to want just enough CYA much more than strict "we know the age of every user". This is the "we're going to put a bouncer out front" stage of the game, not the "police are at the back door and about to raid the bar" stage. It is interesting to me how many have read this PR and jumped to believing it to be the bar raid scenario.


Its particularly interesting for the Australian laws (which don't target Discord yet). The law places responsibility on the targeted platform if they are found with underage users. They must take 'reasonable steps' or face fines. It will be interesting if/when court cases appear. Will easily spoofed or tricked facial scans be considered 'reasonable' by the Australian courts? I think once the dust has settled we will start seeing some court cases and discover how reasonable some of these fig-leaves are.


Even wilder - they're claiming to look at a user's activity on the platform - like what servers they're on, what games they play, and what hours they're active - and infer adulthood from that. No way that'd pass legal muster.


Account age and credit card history can tell a lot. If Discord can assume you were at least 7 when you first signed up for Nitro and you've been a Nitro member off and on since Discord started 11 years ago, you are at least 18.


It seems like these systems would be very easy to reverse engineer. Pretend to be an old person on Discord (whatever that entails) long enough to get them off the case.


I'm curious just how wrong they're going to be about the ages of people who work from home or use a mobile device at work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: